Open to Support Engineer / Security Engineer / Security Operations / SOC roles

Emmanuel Tega
Agbragu

Security Engineer · Security Operations · Linux & Automation

I work across security engineering, security operations, and offensive security. I have hands-on experience with Wazuh, SIEM, Linux environments, TCP/IP, vulnerability management, IDS/IPS, EDR, firewalls, PAM, and DLP. I use Python and Bash to automate security workflows, investigate technical issues, strengthen system configurations, and turn security findings into practical remediation that engineers, users, and decision-makers can act on.

Emmanuel Tega Agbragu
4+ yrs
Security engineering
Wazuh
SIEM · SCA · Compliance
Python + Bash
Automation & scripting
CEH Master
+ eJPT, AWS CCP
MSc
Carnegie Mellon University
whoami

Security engineering built around operations

I’m a cybersecurity engineer with more than four years of experience spanning security operations, enterprise security infrastructure, penetration testing, vulnerability management, and automation. My work has included Linux environments, TCP/IP networking, SIEM, IDS/IPS, EDR, firewalls, privileged access management, data loss prevention, and security monitoring.

During my MSc at Carnegie Mellon University Africa, I gained hands-on experience with Wazuh through the Cybersecurity Operations course. I used Wazuh to monitor a virtualized Windows endpoint, investigate Security Configuration Assessment alerts, identify critical software vulnerabilities, prioritize remediation, and assess security controls against NIST 800-53. I also developed PowerShell remediation scripts for identified configuration weaknesses.

Most recently, as a Security Researcher with the Upanzi Network at CMU-Africa, I conducted security assessments of digital public infrastructure, APIs, AI-backed services, e-commerce platforms, and data portals. Before that, I deployed and supported defensive security infrastructure for banking clients in Lagos. Across both environments, I focus on understanding the technical problem, identifying the root cause, communicating it clearly, and delivering practical remediation.

I work with Python and Bash for security automation and regularly apply frameworks including OWASP, NIST, MITRE ATT&CK, CIS, ISO 27001, and PCI-DSS.

SecOps
Wazuh, SIEM & alert triage
Vulnerability management
Security monitoring
Systems
Linux environments
TCP/IP & network security
Firewalls & virtualization
Automate
Python, Bash, PowerShell
Git & infrastructure tooling
Defense
IDS/IPS & EDR
PAM & DLP
System hardening
Based in
Kigali, Rwanda
Remote & relocation ready
./projects

Selected Security Projects

Hands-on work spanning security operations, SIEM, vulnerability management, automation, public infrastructure security, application security, and AI security.

Critical High Medium Low Informational

Wazuh Security Operations Lab

2024
Carnegie Mellon University Africa · Cybersecurity Operations

Deployed and operated Wazuh to monitor a Windows 11 virtual machine and investigate Security Configuration Assessment alerts. Prioritized security weaknesses based on risk and business impact, developed PowerShell remediation scripts, and used Wazuh vulnerability detection to identify and assess critical software CVEs. Used Wazuh compliance mappings to evaluate monitored systems against NIST 800-53 controls.

Wazuh Security Configuration Assessment Vulnerability Detection NIST 800-53 CIS Benchmarks PowerShell
Environment   Wazuh · Windows 11 · VirtualBox · PowerShell · SIEM
Upanzi Network continental study · published report · named contributor

Named contributor to the Upanzi Network’s published Africa report on the security of public e-government infrastructure, a large-scale automated assessment of 21,782 discoverable subdomains across all 54 African states for misconfigurations, outdated components, cryptographic weaknesses, and data exposure. Led HTTP-method enumeration and built Python automation supporting mass asset discovery and scanning.

Published Research 54 Countries 21,782 Subdomains HTTP Enumeration Python Automation
Role   Contributor, Upanzi Network security team · CMU-Africa

Open Data Portal

Sep 2025
Next.js / nginx data platform · API + LLM feature

Enumerated APIs and client-side JavaScript, mapped hidden endpoints, and tested an AI description-generation feature. Found an indirect prompt injection vulnerability where instructions embedded in uploaded PDFs could influence the model, alongside unauthenticated PII exposure and input-validation weaknesses affecting the datasets API.

LLM01 Prompt Injection PII Exposure Input Validation User Enumeration
Tooling   Nmap · custom API scripts · manual API testing

MojaShop

Feb 2026
E-commerce web app + backend API

Performed authentication, authorization, and business-logic testing of a shopping platform. Identified a mass-assignment flaw in registration that enabled unauthorized privilege escalation and chained it with Broken Object Level Authorization weaknesses exposing sensitive product, customer, and transaction functionality.

Mass Assignment BOLA / IDOR · CVSS 9.1 PII Exposure
Tooling   Burp Suite · authorization testing · JWT analysis

Policy Analyser

Aug 2025
Next.js front end + FastAPI/Uvicorn backend

Discovered an unauthenticated backend API exposed on a non-standard port with public API documentation. Demonstrated unauthorized retrieval and modification of policy data and identified missing security headers. Findings were remediated through the addition of authentication and authorization controls.

Unauthenticated API Unauthorized Data Access Security Headers Remediated
Tooling   Nmap · endpoint discovery · manual API testing

NiD Chatbot Backend

Aug 2025
FastAPI / Flask / LangChain / OpenAI service

Assessed an LLM chatbot backend and Telegram bot codebase through API testing and static review. Identified unauthenticated endpoints, weak cryptographic primitives, outdated dependencies, and unnecessary API schema exposure. Prompt-injection attempts were also evaluated as part of the assessment.

Unauthenticated API Weak Cryptography Dependency Review Static Analysis
Tooling   Nmap · static analysis · dependency review

// Note on disclosure. All assessments shown above were performed in authorized academic, research, or professional environments. Live targets, credentials, internal infrastructure details, and sensitive exploitation information are intentionally excluded. Sanitized supporting material can be provided to prospective employers where appropriate.

./experience

Experience

Four-plus years across security research, technical training, security operations, automation, and enterprise defensive infrastructure.

Security Researcher Upanzi Network, CMU-Africa
Jan 2025 – Apr 2026
Conducted security assessments across web applications, APIs, AI-backed platforms, e-government services, and research systems. Produced technical documentation and proof-of-concept evidence, worked with technical teams to prioritize remediation, and developed Python and Bash automation to support large-scale security testing. Python · Bash · Burp Suite · Nmap · OWASP · NIST
Graduate Teaching Assistant Carnegie Mellon University Africa
Sep 2024 – Jan 2025
Delivered hands-on lab sessions and technical explanations in Ethical Hacking and Cybersecurity Operations, helping students understand security operations, TCP/IP networking, incident response, offensive security concepts, and defensive monitoring workflows. Cybersecurity Operations · Technical Training · TCP/IP · Incident Response
Cybersecurity Engineer Lumenave International, Lagos
Apr 2021 – Jun 2023
Designed, deployed, configured, and supported security infrastructure for regulated banking clients, including IDS/IPS, SIEM, EDR, firewalls, CyberArk PAM, and Symantec DLP. Supported system hardening and security operations, reducing malware infections by 40%. Led five engineers delivering security projects and managed security services. SIEM · IDS/IPS · EDR · Firewalls · CyberArk PAM · Symantec DLP
./skills

What I work with

Security operations, infrastructure, automation, networking, vulnerability management, and offensive security tooling.

Security Operations & SIEM

Wazuh SIEM Elastic Stack Alert Triage SCA Vulnerability Management IDS/IPS EDR Security Monitoring

Linux & Infrastructure

Linux Linux Hardening TCP/IP HTTP DNS Routing Switching VLAN NAT Firewalls Network Troubleshooting Virtualization

Automation & DevOps

Python Bash PowerShell Git Ansible Terraform CloudFormation CI/CD

Cloud & Containers

AWS Azure GCP Docker Kubernetes

Offensive Security & VAPT

Web Application Testing API Security Business Logic Access Control Burp Suite OWASP ZAP Nmap Nessus OpenVAS SQLMap Metasploit

LLM / AI Security

Prompt Injection OWASP LLM Top 10 Model + API Surface AI Application Security

Frameworks & Standards

NIST 800-53 NIST CIS Benchmarks OWASP Top 10 OWASP API MITRE ATT&CK ISO 27001 SOC 2 PCI-DSS

Defensive Security

CyberArk PAM Symantec DLP MISP Security Onion System Hardening Incident Response
./certifications

Certifications & achievements

// Achievements. Top 10 finalist, Greenfist CTF 2023 · Mastercard Foundation Scholar 2023.

./education

Education & coursework

MSc MSc Information Technology Carnegie Mellon University Africa · GPA 3.80/4.0
BSc Pure & Applied Physics University of Benin · First Class Honours · Top 1%
Cybersecurity Operations Carnegie Mellon University Africa
Graduate coursework
Hands-on security operations coursework covering security monitoring and defensive security workflows. Practical work included deploying and using Wazuh, investigating Security Configuration Assessment alerts, vulnerability detection, remediation scripting, virtualized endpoint monitoring, and NIST 800-53 compliance evaluation. Wazuh · SIEM · VirtualBox · PowerShell · NIST 800-53 · CIS
Plaid Shell (C) CMU coursework
Systems programming
Developed a Unix-style command shell in C, including command parsing, tokenization, linked-list command representation, pipelines, process management, and job control, supported by a Python testing harness. C · Python · Make · Linux
./contact

Let’s solve security problems

Open to Support Engineer, Security Engineer, Security Operations, SOC, and related cybersecurity opportunities. I am particularly interested in roles combining Linux systems, security monitoring, automation, troubleshooting, and customer-facing technical problem solving.